RocketChat/Rocket.Chat · error · Meteor.Error

error-not-allowed

error-not-allowed

Error message

Not Allowed

What it means

Thrown by POST /api/v1/rooms.export when the caller has mail-messages permission and the room exists, but the user record is missing or canAccessRoomAsync(room, user) is false: the caller cannot access that room. Typical for private channels, direct messages, and team rooms where the user is not a participant despite holding the export permission.

Solutions

  1. Run the export as a user who is a member of the target room
  2. Add the bot/user to the room before exporting
  3. Filter export targets to rooms the caller subscribes to (subscriptions.get)
  4. Catch and report 'no access' distinctly from 'room missing'

Example fix

// before
await bot.post('rooms.export', { rid: privateRid, type: 'file' }); // bot not in room

// after
const { subscription } = await bot.get('subscriptions.get', { rid: privateRid }).catch(() => ({ subscription: null }));
if (!subscription) await inviteBotToRoom(privateRid); // or use a member's token
await bot.post('rooms.export', { rid: privateRid, type: 'file' });
Defensive patterns

Strategy: validation

Validate before calling

const { subscription } = await sdk.get('subscriptions.get', { rid }).catch(() => ({ subscription: null }));
if (!subscription) throw new Error(`caller cannot access room ${rid} — join it or use a member token`);

Try / catch

try {
  await sdk.post('rooms.export', { rid, type: 'file' });
} catch (e: any) {
  if (e?.response?.data?.errorType === 'error-not-allowed') {
    // no room access: invite the bot/user, or re-run with a member's credentials
  }
  throw e;
}

Prevention

When it happens

Trigger: POST rooms.export with an admin token that has mail-messages but targets a private room that admin is not in (when access checks apply); a bot exporting a DM between two other users; a user removed from a private channel retrying an export.

Common situations: Export tooling assumed to be omniscient because it has the permission, only to hit room-access rules; offboarded users' queued exports firing after removal; bots granted broad permissions but never added to private rooms.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@e4b8178b20 (2026-08-18). Data as JSON: /api/errors/245accf3c37f3c66. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/rooms.ts:1027

			401: validateUnauthorizedErrorResponse,
		},
	},
	async function action() {
		const { rid, type } = this.bodyParams;

		if (!(await hasPermissionAsync(this.user, 'mail-messages', rid))) {
			throw new Meteor.Error('error-action-not-allowed', 'Mailing is not allowed');
		}

		const room = await Rooms.findOneById(rid);
		if (!room) {
			throw new Meteor.Error('error-invalid-room');
		}

		const user = await Users.findOneById(this.userId);

		if (!user || !(await canAccessRoomAsync(room, user))) {
			throw new Meteor.Error('error-not-allowed', 'Not Allowed');
		}

		if (type === 'file') {
			const { dateFrom, dateTo } = this.bodyParams;
			const { format } = this.bodyParams;

			const convertedDateFrom = dateFrom ? new Date(dateFrom) : new Date(0);
			const convertedDateTo = dateTo ? new Date(dateTo) : new Date();
			convertedDateTo.setDate(convertedDateTo.getDate() + 1);

			if (convertedDateFrom > convertedDateTo) {
				throw new Meteor.Error('error-invalid-dates', 'From date cannot be after To date');
			}

			void dataExport.sendFile(
				{
					rid,
					format,

View on GitHub (pinned to e4b8178b20)